I dont know either why is this the default in rails.
In PHP you only have a session id in a cookie. When I first saw how it works in rails (ruby?) it blew my mind.
I don't want to think about how many rails user don't know this and send sensitive data to the client.